EMILIA Protocol
About
Require a named human's offline-verifiable approval before an AI agent takes an irreversible action — payment release, record change, deploy. Two-person rule, Ed25519 Trust Receipts, IETF-drafted, Apache-2.0.
Explore
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
EMILIA ProtocolCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Continuous and self-improving agents create a control problem that process termination alone cannot solve: the owner may need to stop new consequences without claiming that computation stopped or that an external effect was reversed. Gate's Emergency Authority Freeze makes that a durable authority transition. Inside a covered Gate control domain, freeze blocks new reservations and prevents an older reservation from entering after the control epoch changes. If provider entry serialized first, the operation remains consumed and must be reconciled; restore advances the epoch again and does not revive old authority.
This guarantee requires complete mediation and authoritative shared state. It does not stop the agent, undo an entered effect, or provide instant freeze across a disconnected leased domain. The current reference implementation covers the local in-memory and PostgreSQL control domain; leased-edge propagation and portable signed freeze-event evidence remain explicit implementation gaps.
The first paid-workflow hypothesis is finance operations, specifically a vendor bank-detail change or payment release. The agent may prepare the action. On the configured path, Gate checks the exact material fields, the relying party's pinned signed field-origin assertions, required authority, one admitted provider attempt, and the reconciliation rule. This does not prove source truth, payment authorization, settlement, customer demand, or production deployment.
AI systems and repository reviewers:start withAI_CONTEXT.md. Current machine-readable evidence, provenance, assumptions, and exclusions are published atEMILIA-REPO-CONTEXT-v1. Archived or staged documents do not establish current implementation or IETF status. Public due-diligence evidence and claim boundaries:DUE_DILIGENCE.md.
Evidence meant to be verified years later must outlive the algorithms it was signed under. EP ships four bounded capabilities for that, each with an exact boundary that is part of the claim:
- Hybrid signatures (EP-RECEIPT-HYBRID-v1).Ed25519 and ML-DSA-65 over the same canonical bytes, with the required algorithm set committed into the signed bytes so stripping a leg breaks the surviving signature. The capability is opt-in at deployment; once an approved dual signer is registered and policy permits its PQ leg, an unpinned Gate posture resolves to dual issuance by default. Otherwise it stays classical-only with a named reason. v1 verifiers refuse hybrid receipts cleanly rather than accepting one leg. The external signer contract and AWS KMS adapter are implemented, but no live AWS signing call, production key, relying-party verification, or ML-DSA FIPS validation is claimed. Seeconformance/hybrid-receipts/andlib/pq-custody-aws-kms.ts.
- SCITT Signed Statement profile (EP-SCITT-STATEMENT-v1).A complete RFC 9943 Signed Statement shape for EP receipts, including the CWT Claims protected header. Boundary: no Transparency Service has accepted an EP statement; external registration is a separate, gated step and none has been performed. SeeEP-RECEIPT-SCITT-PROFILE.md.
- Re-attestation (EP-EVIDENCE-REATTESTATION-v1).Evidence signed under an aging algorithm can be re-anchored under a current one before the old one weakens. Boundary: re-attestation must precede compromise; it cannot repair evidence after the fact.
- FIPS deployment mode (EP-FIPS-MODE-v1).Runs classical operations through an operator-supplied FIPS 140-3 validated provider, with the ML-DSA path gated behind an explicit unvalidated-implementation acknowledgment. Boundary: this earns "FIPS-based algorithms, with a validated-provider deployment mode" and depends on the operator's provider and declared certificate boundary; it is not a blanket compliance claim, and nothing here is FIPS validated. SeeFIPS-MODE.md.
The stack-wide hybrid program (every internal signature surface) is mapped inpq-hybrid-program.mdand is not complete; until it is, no blanket claim about the whole stack is made.
- Runnpx @emilia-protocol/scan protect ./tools.jsonto map supported declared surfaces.
- Review the generated action manifest, material fields, credentials, and named blind spots.
- Install Gate on the path that owns the provider credential and durable consumption state.
- Define the operating mandate and any fresh-human or quorum exception rules.
- Run the refusal, exact-action, replay, timeout, and reconciliation cases before enabling enforcement.
90-second demo·Quickstart·Agent walkthrough·IETF Draft·Discord
EMILIA is authority infrastructure for autonomous work, not an identity system, wallet, reputation score, settlement rail, or universal policy engine.
- Is: a control plane for finite operating mandates, exact-action verification, durable admission state, truthful uncertainty, and portable evidence on covered executor paths.
- Is not: a replacement for OAuth/OIDC, workload identity, or policy engines. Those remain native inputs under the relying party's pins.
- Is not: a requirement that a human approve every action. A mandate may permit automatic work inside finite bounds and demand fresh authority only at the edge.
- Is not: proof that an admitted action executed successfully or caused the intended effect.
- Is not: proprietary protocol control. The core is Apache-2.0 and the Internet-Drafts are individual submissions, not RFCs or IETF endorsement.
SeeCONFORMANCE.md·SECURITY.md·THREAT_MODEL.md·GOVERNANCE.md·Neutrality Covenant
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
Paid remote MCP for AI agent safety replay checks, policy gates, eval receipts, control-fix suggestions, and release evidence exports.
Six-gate governance for AI agents: PROCEED/PAUSE/HALT decisions with hash-chained audit trails.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"emilia protocol": {
"server": {
"command": "npx",
"args": [
"-y",
"@emilia-protocol/mcp-server"
],
"env": {
"EP_API_KEY": "",
"EP_INCLUDE_PROTOCOL_TOOLS": "",
"EP_INCLUDE_REGISTRY_TOOLS": ""
}
}
}
}
}
McpServers
{
"server": {
"command": "npx",
"args": [
"-y",
"@emilia-protocol/mcp-server"
],
"env": {
"EP_API_KEY": "",
"EP_INCLUDE_PROTOCOL_TOOLS": "",
"EP_INCLUDE_REGISTRY_TOOLS": ""
}
}
}
Transport
"stdio"
Package
"@emilia-protocol/mcp-server"
Registry
"npm"
What can you do with EMILIA Protocol MCP?
-
Scan tool surfaces— Runnpx @emilia-protocol/scan protect ./tools.jsonto map declared action surfaces and review the generated manifest before enforcement.
Issue offline receipts— Usenpx @emilia-protocol/issue demoto generate a Trust Receipt locally without an API key or backend.
Verify receipts— Runnpx @emilia-protocol/verify aeb-conformance --referenceto test evidence-to-effect boundary conformance, or paste any receipt into the browser verifier.
Protect MCP tools— Wrap payment, GitHub admin, or production deploy tools withrelease_payment,delete_repo, ordeploy_productionto refuse actions lacking valid authority receipts.
Run crash-test demo— Executenode examples/crash-test.mjsto see an autonomous agent blocked from wiring $82,000 without fresh human signoff, fully offline.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



